Zloj MCP

Zloj MCP

Details
View on WordPress

Zloj MCP exposes a JSON-RPC HTTP endpoint for MCP clients. Access is gated by a bearer token and an optional per-token IP allow list. Read, create, update, and delete access can be configured per entity (posts, media, and more).

Each access token belongs to one WordPress user. Tool calls run with that user’s capabilities, and content created through MCP is authored by that user. The author cannot be overridden. Users can be listed and read; the plugin does not create, update, or delete WordPress users.

Settings are on Settings Zloj MCP (administrators only). Several tokens can be stored; each is a salt and hash, and the owner’s user ID is part of the hash. Changing that user ID in the database makes the token stop working. A token migrated from older single-token storage is not bound this way until you delete it and create a new one. The owner of an existing token cannot be changed in the settings screen.

MCP tools

Read: post_type_list, post_list, post_get, user_list, user_get, term_list, media_list, comment_list, comment_get.

Write (when enabled): post_create, post_update, post_delete, media_sideload, media_update, media_delete, comment_create, comment_update, comment_approve, comment_spam, comment_delete.

Post meta is read and written via the meta field on the post tools. User meta is read-only via user_get / user_list.

Details

Plugin code:
zloj-mcp
Plugin version:
0.3.11
Author:
Outdated:
No
WP version:
6.2 or higher
PHP version:
7.4 or higher
Test up to WP version:
7.1.2
Total installations:
0
Last updated:
2026-09-29
Rating:
Times rated:
0
ai
api
automation
mcp
rest